Security Bulletin
Summary
libssh2 is used by Power Hardware Management Console (HMC). HMC has addressed the applicable CVE.
Vulnerability Details
CVEID: CVE-2019-3862
DESCRIPTION: An out of bounds read flaw was discovered in libssh2 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a denial of service or read data in the client memory.
CVSS Base Score: 7.3
CVSS3 Base Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector: Network
Access Vector (AV): Network
Affected Products and Versions
Power HMC V8.7.0.0
Power HMC V9.1.910.0
Remediation/Fixes
Remediation/Fixes
The following fixes are available on IBM Fix Central at: http://www-933.ibm.com/support/fixcentral/
Product
|
VRMF
|
APAR
|
Remediation/Fix
|
Power HMC
|
V8.8.7.0 SP3 ppc
|
MB04223
|
|
Power HMC
|
V8.8.7.0 SP3 x86
|
MB04222
|
|
Power HMC
|
V9.1.930.0 SP1 ppc
|
MB04220
|
|
Power HMC
|
V9.1.930.0 SP1 x86
|
MB04219
|
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
References
Change History
Initial Version: 29 Aug 2019
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Was this topic helpful?
Document Information
Modified date:
22 September 2021
UID
ibm11072240